All the mail mirrored from lore.kernel.org
 help / color / mirror / Atom feed
* Interested in ceph OSD encryption and key management
@ 2015-05-28  4:23 Andrew Bartlett
  2015-05-28 20:03 ` Sage Weil
  0 siblings, 1 reply; 10+ messages in thread
From: Andrew Bartlett @ 2015-05-28  4:23 UTC (permalink / raw)
  To: ceph-devel

David Disseldorp was good enough to point me at this proposal for ceph
OSD key management:
https://wiki.ceph.com/Planning/Blueprints/Infernalis/osd%3A_simple_ceph-mon_dm-crypt_key_management

I'm really interested in improving ceph on-disk encryption, and am
really glad folks are taking this beyond the local key storage we have
managed so far. 

So I can be part of the discussion, how do I get a login to the wiki?  I
would like to indicate my interest there.

Regarding the proposal:

In the default mode suggested in the wiki, my primary concern is that
I'm told, in a number of deployments, the monitor node is the same
server that also holds the OSDs, so we don't gain anything for those
cases over the /etc storage.

In those cases, the hooks suggested in the wiki will be key, as will be
having those configurable in ceph.conf, so ceph-deploy can just pass it
down to all the nodes as they are built, just as the other dmcrypt
options are.  

I would like to see three things hookable:
 - the command to obtain the key (on stdout)
 - to encrypt the key (so we can additionally pass it
via gpg, a HSM or remote encrypt/decrypt service)
 - to decrypt the key


Thanks,

Andrew Bartlett


-- 
Andrew Bartlett
http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba





^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2015-06-18 14:31 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-05-28  4:23 Interested in ceph OSD encryption and key management Andrew Bartlett
2015-05-28 20:03 ` Sage Weil
2015-05-31 14:01   ` Wyllys Ingersoll
2015-06-03  0:07     ` Andrew Bartlett
2015-06-03  0:12   ` Andrew Bartlett
2015-06-03  5:39     ` Milan Broz
2015-06-17  2:37   ` Andrew Bartlett
2015-06-17  4:16     ` Sage Weil
2015-06-18 13:34       ` Milan Broz
2015-06-18 14:31         ` Sage Weil

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.